Microsoft Windows 9x Plaintext Credential Cache Vulnerability
BID:829
Info
Microsoft Windows 9x Plaintext Credential Cache Vulnerability
| Bugtraq ID: | 829 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 29 1999 12:00AM |
| Updated: | Nov 29 1999 12:00AM |
| Credit: | Publicized in Microsoft advisory MS99-052 released November 29, 1999. |
| Vulnerable: |
Microsoft Windows 98 Microsoft Windows 95 |
| Not Vulnerable: |
Microsoft Windows 98SE |
Discussion
Microsoft Windows 9x Plaintext Credential Cache Vulnerability
Windows 95 and 98 cache a user's name and password in plaintext in RAM. This feature was included for backwards compatibility with Windows for Workgroups, which implemented this mechanism for use with the 'net' program, which handled most network configuration requirements for the WfW OS. This feature can be exploited via specific function calls to retrieve another user's credentials. In order for this to work , the attacker must have console access to the target machine, and it must not have been rebooted since the last logout. Only the most recent user's credentials can be retrieved.
Windows 95 and 98 cache a user's name and password in plaintext in RAM. This feature was included for backwards compatibility with Windows for Workgroups, which implemented this mechanism for use with the 'net' program, which handled most network configuration requirements for the WfW OS. This feature can be exploited via specific function calls to retrieve another user's credentials. In order for this to work , the attacker must have console access to the target machine, and it must not have been rebooted since the last logout. Only the most recent user's credentials can be retrieved.
Exploit / POC
Microsoft Windows 9x Plaintext Credential Cache Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows 9x Plaintext Credential Cache Vulnerability
References:
References: